I hope that the author notified Criticker about these issues before putting them out there on the internet. Not doing so would be extremely irresponsible and is sort of screwing over the users of Cricketer.
He claims to have notified Criticker in 2010, and links to a post on their forum (username teario): http://www.criticker.com/forum/viewtopic.php?f=8&t=2063#p188...
It will also be interesting to see if the company makes any warning that the average user will understand (e.g. "don't reuse your Criticker password on other sites, especially email or financial, because your password here is not secret, at all").